Microsoft and Coinbase have dismantled EvilTokens, a subscription-based phishing-as-a-service platform that used AI to compromise more than 12,000 email inboxes across 10,000-plus organizations worldwide since February 2026, and traced roughly $1.1 million in proceeds through crypto payments before two men were arrested in the U.K.
Microsoft said the service was designed to make business email compromise faster and easier by bringing account compromise, mailbox analysis, reconnaissance and fraud preparation into one subscription-based platform. Customers could reportedly access the service through Telegram after paying a $1,500 initial fee and $500 monthly subscription.
The scale of the operation was amplified by artificial intelligence. Instead of forcing attackers to manually read hundreds or thousands of messages after compromising an account, the platform could summarize and translate emails, identify trusted contacts, map organizational roles and locate conversations involving invoices or wire transfers.
Microsoft Digital Crimes Unit executive Steven Masada said the platform’s AI went beyond simply generating phishing emails. It could help criminals determine “who to target, who to impersonate” and how to exploit trusted relationships to pursue fraud EvilTokens.
EvilTokens exploited legitimate Microsoft authentication
At the center of the operation was an abuse of Microsoft’s device-code authentication process.
Device-code authentication is a legitimate feature intended for devices with limited interfaces, including smart TVs, printers and conferencing equipment. In a normal scenario, a user receives a code and enters it through a browser to authenticate a legitimate device.
Attackers instead initiated the authentication request and embedded the resulting code into convincing phishing campaigns. Victims were directed to Microsoft’s legitimate login page and persuaded to enter the code, unknowingly authorizing a session controlled by the attacker. Microsoft said the technique allowed criminals to obtain authenticated access without directly stealing the victim’s password.
The phishing messages used familiar business themes, including invoices, shared documents, requests for proposals and other routine communications. Microsoft identified 44 different themes used by the service and said the campaigns employed malicious URLs, PDF attachments and HTML files.
Once inside an inbox, EvilTokens could help attackers identify employees with financial authority, discover payment-related conversations and determine which trusted individuals could be impersonated. In some cases, attackers also created malicious inbox rules or registered devices to maintain access.
Microsoft tracks the threat actor behind the development and support of the platform as Storm-2992.
Coinbase follows the crypto money trail
The investigation took another turn when Coinbase’s Global Intelligence team began following the cryptocurrency payments associated with EvilTokens.
Coinbase said it traced approximately $1.1 million in platform revenue across four Tron addresses between October 2025 and June 2026. Investigators identified more than 1,000 deposits from over 700 distinct addresses and followed the movement of funds from payments into the service through to eventual cash-out destinations.
The $1.1 million figure represents revenue generated by the alleged phishing service, rather than the total amount stolen from its victims.
Coinbase said its investigators combined blockchain transaction data with test transactions, merchant records, device information and open-source intelligence to help identify the alleged operators. The findings were then referred to London’s Metropolitan Police.
The crypto exchange also investigated customers it identified as purchasers of the service and referred relevant cases to law enforcement. Coinbase said its evidence supported Microsoft’s civil action, which resulted in the seizure of 50 websites and the disabling of more than 175 domains connected to the operation.
Coinbase customers were also affected indirectly. The exchange said some users were manipulated through compromised email conversations into sending cryptocurrency to scam-controlled addresses, although Coinbase accounts and credentials themselves were not compromised.
Takedown exposes the next phase of AI-enabled cybercrime
The disruption involved a broad coalition of technology companies, security organizations and law enforcement agencies. Microsoft said the operation was authorized by the U.S. District Court for the Eastern District of Virginia and involved partners including Coinbase, Cloudflare, OpenAI, Railway, SpyCloud, the Shadowserver Foundation, TRM Labs and Health-ISAC.
British authorities also arrested two men, aged 32 and 38, on September 11 in connection with the alleged operation. Microsoft said both were subsequently released on police bail while the investigation continues.
The case demonstrates why cryptocurrency tracing has become an increasingly important component of cybercrime investigations. Blockchain transactions can leave a financial trail even when criminals operate through pseudonymous addresses and online identities.
It also highlights a broader concern around AI and cybercrime. EvilTokens did not merely automate the creation of deceptive messages; it helped attackers interpret compromised data and turn that information into targeted fraud strategies. Microsoft investigators also found evidence that portions of the platform itself were built with AI-assisted coding tools.
Coinbase said the operator had indicated plans to expand the toolkit toward Gmail and Okta accounts, suggesting the underlying business model could extend beyond Microsoft environments.
Microsoft recommends that organizations restrict device-code authentication where it is not required, revoke refresh tokens following suspected compromise and force affected users to reauthenticate. Coinbase separately advises organizations to independently verify changes to payment instructions and use phishing-resistant authentication such as passkeys or hardware security keys.
The infrastructure behind EvilTokens has now been disrupted, but the techniques it exposed remain relevant. For security teams, the immediate challenge is not simply removing malicious domains; it is detecting whether stolen sessions, tokens and inbox access survived the takedown.